NordVPN Promotion

Home / News

DNS Hijacks Across Three ccTLDs Linked to 32 Unauthorized HTTPS Certificates

A new examination of public Certificate Transparency (CT) logs has identified 32 unauthorized HTTPS certificates issued during attacks on the country-code top-level domains (ccTLDs) of Ghana, Sierra Leone and American Samoa. The findings provide a more detailed account of incidents in which attackers manipulated authoritative DNS records to obtain trusted certificates for domains belonging to Google and other major organizations.

The 32 certificates were issued between September 22 and 27. According to an October 8 report by iTnews, the publication identified the certificates by comparing public CT records with Chrome’s certificate blocklist. The analysis suggests that Ghana’s .gh namespace was compromised first, on September 22, followed by Sierra Leone’s .sl on September 25 and American Samoa’s .as on September 27. Most certificates associated with each incident were issued within approximately 90 minutes.

The certificates reportedly included wildcard certificates issued through Let’s Encrypt and Sectigo’s ZeroSSL service. iTnews also identified a certificate issued through Cloudflare’s certificate authority for a domain associated with another major technology company. The publication’s count has not been independently reproduced.

The attacks exploited control over authoritative DNS. In an October 6 security disclosure, Google confirmed that attackers had altered DNS records within the three affected namespaces and obtained certificates covering several Google domains and domains belonging to other organizations.

Certificate authorities rely on domain-control validation to establish whether an applicant is authorized to obtain a certificate. When attackers control the DNS records used in that process, they can potentially satisfy validation checks without authorization from the legitimate domain owner.

Google emphasized that the incidents did not involve a compromise of its own systems and said it had no reason to believe the issuing certificate authorities acted improperly.

Chrome blocked the unauthorized certificates. Google said it used Chrome’s CRLSet mechanism to prevent affected certificates from being trusted and worked with issuing authorities to secure their revocation. It subsequently identified additional potentially affected organizations through CT monitoring and extended its blocking measures.

The certificates have since been revoked, according to iTnews. Google nevertheless cautioned that browser-side protections cannot guarantee detection of every affected domain or protect users of all browsers and applications.

The incidents expose a dependency between DNS integrity and HTTPS trust. A certificate can be issued through an otherwise legitimate validation process when the underlying DNS information has been compromised. If attackers can also redirect traffic, an unauthorized certificate may enable convincing impersonation of the affected website.

Google recommends that domain owners continuously monitor CT logs across their entire domain portfolios, including parked domains and regional registrations. It also advises deploying restrictive Certification Authority Authorization (CAA) records with account-specific controls.

Google noted that CAA records cannot necessarily prevent issuance during an active DNS hijack, but properly configured restrictions can help prevent further unauthorized issuance after legitimate DNS control is restored.

The precise methods used to compromise the three ccTLD namespaces remain undisclosed. iTnews reported receiving no responses from the affected registry operators before publication. The registry-level incident timelines, the full inventory of affected domains and the extent of any resulting traffic interception have not been established publicly.

By CircleID Reporter —

CircleID’s internal staff reporting on news tips and developing stories. Do you have information the professional Internet community should be aware of? Contact us.

Visit Page

Filed Under

Comments

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

DNS

Sponsored byDNIB.com

New TLDs

Sponsored byRadix

IPv4 Markets

Sponsored byIPv4.Global

DNS Security

Sponsored byWhoisXML API

Brand Protection

Sponsored byCSC

Cybersecurity

Sponsored byVerisign

Domain Names

Sponsored byVerisign

NordVPN Promotion